PT-2020-1634 · Eclipse · Eclipse Memory Analyzer

Iassen Minov

·

Published

2020-01-17

·

Updated

2020-01-24

·

CVE-2019-17634

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Memory Analyzer versions 1.9.1 and earlier
Description The issue is related to errors in processing specially crafted HTML requests in the reporting component of the Eclipse Memory Analyzer software for Java application analysis. Exploitation of this issue may allow a remote attacker to execute arbitrary code on the target system. The vulnerability can be triggered when a user generates an HTML report from a malicious heap dump, which could be specially crafted or come from a crafted application or an application processing malicious data. This can occur when a report is generated and opened from the Memory Analyzer graphical user interface or when a report generated in batch mode is then opened in Memory Analyzer or by a web browser.
Recommendations For Eclipse Memory Analyzer versions 1.9.1 and earlier, avoid generating HTML reports from untrusted heap dumps until a fix is available. As a temporary workaround, consider disabling the HTML report generation feature in the Memory Analyzer graphical user interface to minimize the risk of exploitation. Restrict access to the reporting component to prevent potential attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00840
CVE-2019-17634

Affected Products

Eclipse Memory Analyzer